News aggregator

Vuln: Cisco RV110W/RV130W/RV215W Routers Management Interface CVE-2018-0423 Buffer Overflow Vulnerability

SecurityFocus Vulnerabilities - Wed, 09/05/2018 - 00:00
Cisco RV110W/RV130W/RV215W Routers Management Interface CVE-2018-0423 Buffer Overflow Vulnerability
Categories: Security News

CVE-2018-6554

National Vulnerability Database - Tue, 09/04/2018 - 14:29
Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (memory consumption) by repeatedly binding an AF_IRDA socket.
Categories: Security News

CVE-2018-6555

National Vulnerability Database - Tue, 09/04/2018 - 14:29
The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (ias_object use-after-free and system crash) or possibly have unspecified other impact via an AF_IRDA socket.
Categories: Security News

CVE-2018-6923

National Vulnerability Database - Tue, 09/04/2018 - 14:29
In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p2, 11.1-RELEASE-p13, ip fragment reassembly code is vulnerable to a denial of service due to excessive system resource consumption. This issue can allow a remote attacker who is able to send an arbitrary ip fragments to cause the machine to consume excessive resources.
Categories: Security News

CVE-2018-7990

National Vulnerability Database - Tue, 09/04/2018 - 12:29
Mate10 Pro Huawei smart phones with the versions before 8.1.0.326(C00) have a FRP bypass vulnerability. During the mobile phone reseting process, an attacker could bypass "Find My Phone" protect after a series of voice and keyboard operations. Successful exploit could allow an attacker to bypass FRP.
Categories: Security News

CVE-2018-10929

National Vulnerability Database - Tue, 09/04/2018 - 12:29
A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create arbitrary files and execute arbitrary code on glusterfs server nodes.
Categories: Security News

CVE-2018-10930

National Vulnerability Database - Tue, 09/04/2018 - 12:29
A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.
Categories: Security News

CVE-2018-11262

National Vulnerability Database - Tue, 09/04/2018 - 12:29
In Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel while trying to find out total number of partition via a non zero check, there could be possibility where the 'TotalPart' could cross 'GptHeader->MaxPtCnt' and which could result in OOB write in patching GPT.
Categories: Security News

CVE-2018-7936

National Vulnerability Database - Tue, 09/04/2018 - 12:29
Mate 10 Pro Huawei smart phones with the versions before BLA-L29 8.0.0.148(C432) have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can connect the phone with PC and send special instructions to install third party desktop and disable the boot wizard. As a result, the FRP function is bypassed.
Categories: Security News

CVE-2018-7937

National Vulnerability Database - Tue, 09/04/2018 - 12:29
In Huawei HiRouter-CD20-10 with the versions before 1.9.6 and WS5200-10 with the versions before 1.9.6, there is a plug-in signature bypass vulnerability due to insufficient plug-in verification. An attacker may tamper with a legitimate plug-in to build a malicious plug-in and trick users into installing it. Successful exploit could allow the attacker to obtain the root permission of the device and take full control over the device.
Categories: Security News

CVE-2018-7938

National Vulnerability Database - Tue, 09/04/2018 - 12:29
P10 Huawei smartphones with the versions before Victoria-AL00AC00B217 have an information leak vulnerability due to the lack of permission validation. An attacker tricks a user into installing a malicious application on the smart phone, and the application can read some hardware serial number, which may cause sensitive information leak.
Categories: Security News

CVE-2018-10924

National Vulnerability Database - Tue, 09/04/2018 - 11:29
It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.
Categories: Security News

CVE-2018-10926

National Vulnerability Database - Tue, 09/04/2018 - 11:29
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on a glusterfs server node.
Categories: Security News

CVE-2018-10927

National Vulnerability Database - Tue, 09/04/2018 - 11:29
A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster brick process.
Categories: Security News

CVE-2018-10928

National Vulnerability Database - Tue, 09/04/2018 - 11:29
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.
Categories: Security News

CVE-2018-10911

National Vulnerability Database - Tue, 09/04/2018 - 10:29
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
Categories: Security News

CVE-2018-10913

National Vulnerability Database - Tue, 09/04/2018 - 10:29
An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.
Categories: Security News

CVE-2018-10914

National Vulnerability Database - Tue, 09/04/2018 - 10:29
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.
Categories: Security News

CVE-2018-10923

National Vulnerability Database - Tue, 09/04/2018 - 10:29
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs server node.
Categories: Security News

CVE-2018-10907

National Vulnerability Database - Tue, 09/04/2018 - 09:29
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause crash or potential code execution.
Categories: Security News

Pages